Both Jared and Alberto are correct. In the ISE admin guide, Active Directory Account Permissions Required for Performing Various Operations lists out the permissions.
... View more
Hi Does anyone knows where to get information about a Firepower IPS?, Ive been getting a lot of signatures from my IDS like BLACKLIST DNS request for known malware domain did.ijinshan.com - Win.Trojan.Jadtre (1:33881:1) BLACKLIST User-Agent known malicious user-agent - Microsoft Internet Explorer - Win.Trojan.Backspace (1:35569:1) OS-OTHER Bash CGI environment variable injection attempt (1:31978:4) and similar The issue is that I cannot find any centralized db for the signatures, I only found in other databases like sophos and the like. Is there any webpage or centralized database where I can found the complete description of the signature database from SNort-Sourcefire? Thanks. Your help is much appreciated.
... View more
Hello Alberto. you're asking about the "critical VLAN" feature. As this is a spanish language community I will answer in spanish. WLC con el sistema operativo AirOS tradicional no tiene la funcionalidad "critical VLAN". Yo he preguntado algunas veces a la business unit y me dijeron que esta funcionalidad no está siquiera en roadmap. Por otro lado los nuevos modelos de WLC tienen el nuevo sistema operativo IOS-XE. Puedes ver el siguiente link donde se aprecia que estos WLC sí tienen esta funcionalidad http://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/crit-vce-vlan-supp.html Por favor califica este post si fue útil.
... View more
Hello, I went through your query and for the same I have found the link below which may help in solving it:- http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_client_prov.html
... View more
Helo Alberto, as you get access to the internal webserver on an IEA, basically everything can be configured, even the web frontend. However, most of those things require editing of the files, as customisation is not part of the administration GUI. Hope that helps, Andreas
... View more
Hi, im having a hard time trying to send traps on ACS5.2, I have a VM for lab purposes and seem to do nothing when I configure the snmp-server commands (I have a trap collector that works fine with routers, switches etc), however the final purpose is to emulate an appliance 1121 that will be installed in the near future, is there any issue on ACS mounted on VM?? or does the ACS5.2 do not send any traps?? Regads Alberto
... View more
I believe the information you're looking for can be found here: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html Specifically in table 7: Feature ASA 5585-X with SSP-10 Maximum Firewall Throughput 4 Gbps Maximum Firewall Throughput (muti-protocol) 3 Gbps Maximum Firewall and IPS Throughput 2 Gbps (with IPS SSP-10) Maximum VPN Throughput 1 Gbps Concurrent Sessions 1,000,000 Hope that helps!!
... View more
Hi Alberto Thank you for your additional info regarding keepalive config and sorry for my insensitive request regarding show tech. Probably, many scripted keepalive config cause high cpu. When I configured 50 services with scripted keepalive, cpu utilization went 78%. (Since I configure keepalive frequesncy 2, my CSS may waste cpu utilization than yours.) Full configuration of my lab is attached. I checked this behavior with 8.20(402). CSS11503-A(debug)# show system-resources cpu_summary Chassis CPU Utilizations Name Slot Sub 5Sec 1Min 5Min -------------------------------------------- CSS5-SCM-2GE B0 1 1 78% 78% 69% CSS5-IOM-8FE B0 2 1 0% 0% 0% CSS5-SSL-C-K9 B0 3 1 0% 0% 0% CSS11503-A(debug)# shell 1 1 spyReport | grep -v "0%" NAME ENTRY TID PRI total % (ticks) delta % (ticks) -------- -------- ----- --- --------------- --------------- apIdle 8c184700 255 94% (24133648) 28% ( 14) KERNEL 1% ( 358764) 2% ( 1) There is Guideline for scripted keepalive on the following URL. You may be able to reduce cpu utilization to tune keepalive frequency. http://www.cisco.com/en/US/products/hw/contnetw/ps792/prod_bulletin09186a008017bb55.html Regarding high cpu bug, I could only find CSCtb45641 after 8.20(303). However, it's very rare case. So, probably your problem doesn't hit this bug. I guess your issue is related to scripted keepalive config (number, frequency and interval) as with my test result.
... View more